Guide
How to manage event photography consent under GDPR
Manage event photography consent by separating 'we take photos' from 'we offer selfie matching', giving a real opt-out, recording what you told people, and deleting templates when matching ends. Relivo implements the matching consent in-product; you still own attendee communication.
Last updated August 2026
Two notices, not one
Notice A: photography is happening, who the controller is, how to object to being featured in a recap film. Notice B: optional selfie matching, biometric processing, Relivo as processor, retention, deletion.
Operational checklist
Use this as a starting list for your DPIA, then have counsel edit it.
- Name the controller on tickets and on site
- Link /privacy and the matching explanation before the selfie
- Do not bundle matching into unrelated 'I agree' checkboxes
- Train registration staff not to pressure people into a selfie
- Honor deletion requests on a defined SLA
- Keep a record of the consent text version shown
What to do next
Read /guides/facial-recognition-events-gdpr and /dpa. Put counsel on the hook for the DPIA. Do not ship matching in a country or context you have not reviewed.
FAQ
- Can we buy consent with a prize draw?
- Paying for biometric consent is legally and ethically fraught. Relivo's public stance on reviews is the same spirit: do not incentivize the outcome. Ask counsel.